7.5
    High

    CVE-2008-3784

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows remote attackers to execute arbitrary SQL commands via the info_hash parameter.

    Source:InATeam
    Published:26 Aug 2008
    6.8
    Medium

    CVE-2008-3783

    Last Modified: 30 Mar 2017

    Multiple SQL injection vulnerabilities in index.php in Matterdaddy Market 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) type parameters.

    Source:~!Dok_tOR!~
    Published:26 Aug 2008
    7.5
    High

    CVE-2008-3780

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in recommend.php in Five Star Review Script allows remote attackers to execute arbitrary SQL commands via the item_id parameter.

    Source:Mr.SQL
    Published:26 Aug 2008
    4.3
    Medium

    CVE-2008-3779

    Last Modified: 20 Dec 2016

    Cross-site scripting (XSS) vulnerability in search/index.php in Five Star Review Script allows remote attackers to inject arbitrary web script or HTML via the words parameter in a search action.

    Source:Mr.SQL
    Published:26 Aug 2008
    5
    Medium

    CVE-2008-3776

    Last Modified: 16 Mar 2014

    Directory traversal vulnerability in Fujitsu Web-Based Admin View 2.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Source:Deniz Cevik
    Published:25 Aug 2008
    7.5
    High

    CVE-2008-3774

    Last Modified: 16 Mar 2014

    SQL injection vulnerability in index.php in Simasy CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:r45c4l
    Published:22 Aug 2008
    4.3
    Medium

    CVE-2008-3773

    Last Modified: 16 Mar 2014

    Cross-site scripting (XSS) vulnerability in vBulletin 3.7.2 PL1 and 3.6.10 PL3, when "Show New Private Message Notification Pop-Up" is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a private message subject (aka newpm[title]).

    Source:Core Security
    Published:22 Aug 2008
    7.5
    High

    CVE-2008-3772

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in categories_portal.php in Pars4u Videosharing 1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Source:Mr.SQL
    Published:22 Aug 2008
    4.3
    Medium

    CVE-2008-3771

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in members.php in Pars4u Videosharing 1 allows remote attackers to inject arbitrary web script or HTML via the PageNo parameter.

    Source:Mr.SQL
    Published:22 Aug 2008
    6.8
    Medium

    CVE-2008-3770

    Last Modified: 14 Mar 2014

    Multiple directory traversal vulnerabilities in Freeway 1.4.1.171, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to (1) includes/events_application_top.php; (2) english/account.php, (3) french/account.php, and (4) french/account_newsletters.php in includes/languages/; (5) includes/modules/faqdesk/faqdesk_article_require.php; (6) includes/modules/newsdesk/newsdesk_article_require.php; (7) card1.php, (8) loginbox.php, and (9) whos_online.php in templates/Freeway/boxes/; and (10) templates/Freeway/mainpage_modules/mainpage.php. NOTE: vector 1 may be the same as CVE-2008-3677.

    Source:Digital Security Research Group
    Published:22 Aug 2008
    7.5
    High

    CVE-2008-3768

    Last Modified: 5 Jan 2018

    Multiple SQL injection vulnerabilities in class.ajax.php in Turnkey Web Tools SunShop Shopping Cart before 4.1.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in an edit_registry action to index.php, (2) a vector involving the check_email function, and other vectors.

    Source:GulfTech Security
    Published:22 Aug 2008
    7.5
    High

    CVE-2008-3767

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in classified.php in phpBazar 2.0.2 allows remote attackers to execute arbitrary SQL commands via the adid parameter.

    Source:e.wiZz!
    Published:22 Aug 2008
    7.5
    High

    CVE-2008-3765

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:21 Aug 2008
    7.5
    High

    CVE-2008-3764

    Last Modified: 5 Jan 2018

    Eval injection vulnerability in globalsoff.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary PHP code via the test parameter, and probably arbitrary parameters, to chat.php.

    Source:GulfTech Security
    Published:21 Aug 2008
    6.8
    Medium

    CVE-2008-3763

    Last Modified: 5 Jan 2018

    Variable overwrite vulnerability in libsecure.php in Turnkey PHP Live Helper 2.0.1 and earlier, when register_globals is enabled, allows remote attackers to overwrite arbitrary variables related to the db config file. NOTE: this can be leveraged for code injection by overwriting the language file.

    Source:GulfTech Security
    Published:21 Aug 2008
    7.5
    High

    CVE-2008-3762

    Last Modified: 5 Jan 2018

    SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the dep parameter, related to lack of input sanitization in the get function in global.php.

    Source:GulfTech Security
    Published:21 Aug 2008
    4.9
    Medium

    CVE-2008-3761

    Last Modified: 20 Dec 2016

    hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 uses the METHOD_NEITHER communication method for IOCTLs, which allows local users to cause a denial of service via a crafted IOCTL request.

    Source:g_
    Published:21 Aug 2008
    4.3
    Medium

    CVE-2008-3758

    Last Modified: 5 Jan 2018

    Multiple cross-site scripting (XSS) vulnerabilities in Lussumo Vanilla 1.1.4 and earlier (1) allow remote attackers to inject arbitrary web script or HTML via the NewPassword parameter to people.php, and allow remote authenticated users to inject arbitrary web script or HTML via the (2) Account picture and (3) Icon fields in account.php. NOTE: some of these details are obtained from third party information.

    Source:GulfTech Security
    Published:21 Aug 2008
    7.5
    High

    CVE-2008-3756

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in tr.php in YourFreeWorld Viral Marketing Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:21 Aug 2008
    7.5
    High

    CVE-2008-3755

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view.php in YourFreeWorld Classifieds Script allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Source:Hussin X
    Published:21 Aug 2008
    7.5
    High

    CVE-2008-3754

    Last Modified: 15 Mar 2014

    SQL injection vulnerability in trl.php in YourFreeWorld Stylish Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Charalambous Glafkos
    Published:21 Aug 2008
    7.5
    High

    CVE-2008-3752

    Last Modified: 15 Mar 2014

    SQL injection vulnerability in tr.php in YourFreeWorld Ad-Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:21 Aug 2008
    7.5
    High

    CVE-2008-3750

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in tr.php in YourFreeWorld URL Rotator Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:21 Aug 2008
    7.5
    High

    CVE-2008-3749

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in tr.php in YourFreeWorld Banner Management Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:S.W.A.T.
    Published:21 Aug 2008
    7.5
    High

    CVE-2008-3748

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_group.php in Active PHP Bookmarks (APB) 1.1.02 and 1.2.06 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:21 Aug 2008
    9.3
    Critical

    CVE-2008-3734

    Last Modified: 23 Apr 2026

    Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in a connection greeting (response).

    Source:securfrog
    Published:20 Aug 2008
    9.3
    Critical

    CVE-2008-3733

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in EO Video (eo-video) 1.36 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a .eop (aka playlist) file with a ProjectElement element that contains a long Name element.

    Source:j0rgan
    Published:20 Aug 2008
    9.3
    Critical

    CVE-2008-3732

    Last Modified: 23 Nov 2016

    Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

    Source:g_
    Published:20 Aug 2008
    7.5
    High

    CVE-2008-3725

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in trr.php in YourFreeWorld Ad Board Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:20 Aug 2008
    6.3
    Medium

    CVE-2008-3723

    Last Modified: 14 Mar 2014

    Directory traversal vulnerability in index.php in PHPizabi 0.848b C1 HFP3 allows remote authenticated administrators to read arbitrary files via (1) a .. (dot dot), (2) a URL, or possibly (3) a full pathname in the id parameter in an admin.templates.edittemplate action. NOTE: some of these details are obtained from third party information.

    Source:Lostmon
    Published:20 Aug 2008
    7.5
    High

    CVE-2008-3722

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in forum/neu.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the kat parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:U238
    Published:20 Aug 2008
    7.5
    High

    CVE-2008-3721

    Last Modified: 21 Dec 2016

    PHP remote file inclusion vulnerability in user_language.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary PHP code via a URL in the language_dir parameter.

    Source:Khashayar Fereidani
    Published:20 Aug 2008
    7.5
    High

    CVE-2008-3720

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in index.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the id vector is already covered by CVE-2007-5679.

    Source:Khashayar Fereidani
    Published:20 Aug 2008
    7.5
    High

    CVE-2008-3719

    Last Modified: 17 Nov 2016

    SQL injection vulnerability in directory.php in SFS Affiliate Directory allows remote attackers to execute arbitrary SQL commands via the id parameter in a deadlink action.

    Source:Hussin X
    Published:20 Aug 2008
    6.5
    Medium

    CVE-2008-3718

    Last Modified: 21 Dec 2016

    Multiple SQL injection vulnerabilities in cyberBB 0.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter to show_topic.php and the (2) user parameter to profile.php.

    Source:cOndemned
    Published:20 Aug 2008
    2.6
    Low

    CVE-2008-3715

    Last Modified: 14 Mar 2014

    Cross-site scripting (XSS) vulnerability in inc-core-admin-editor-previouscolorsjs.php in the FlexCMS 2.5 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the PreviousColorsString parameter.

    Source:Dr.Crash
    Published:19 Aug 2008
    4.3
    Medium

    CVE-2008-3714

    Last Modified: 14 Mar 2014

    Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.

    Source:Morgan Todd
    Published:23 Jun 2008
    7.5
    High

    CVE-2008-3713

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in product.php in PHPBasket allows remote attackers to execute arbitrary SQL commands via the pro_id parameter.

    Source:r45c4l
    Published:19 Aug 2008
    2.6
    Low

    CVE-2008-3712

    Last Modified: 14 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.2 and 4.6.5, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) query string to mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php and the (2) mosConfig_sitename parameter to administrator/popups/index3pop.php.

    Source:Khashayar Fereidani
    Published:19 Aug 2008
    7.5
    High

    CVE-2008-3711

    Last Modified: 15 Nov 2016

    SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a browse action.

    Source:Hussin X
    Published:19 Aug 2008
    4.3
    Medium

    CVE-2008-3708

    Last Modified: 20 Dec 2016

    Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter to (1) news/index.dot and (2) getting_started/macros/macros_detail.dot.

    Source:Don
    Published:19 Aug 2008
    7.5
    High

    CVE-2008-3706

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in bannerclick.php in ZEEJOBSITE 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.

    Source:Hussin X
    Published:19 Aug 2008
    9.3
    Critical

    CVE-2008-3704

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."

    Source:Symantec
    Published:18 Aug 2008
    9.3
    Critical

    CVE-2008-3702

    Last Modified: 21 Dec 2016

    Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used in products such as SpeedBit Download Accelerator Plus (DAP) 8.6, allow remote attackers to execute arbitrary code via a long argument to the (1) ReadGIF or (2) ReadGIF2 method.

    Source:Guido Landi
    Published:15 Aug 2008
    6.5
    Medium

    CVE-2008-3701

    Last Modified: 5 Jan 2018

    SQL injection vulnerability in staff/index.php in Kayako SupportSuite 3.20.02 and earlier allows remote authenticated users to execute arbitrary SQL commands via the customfieldlinkid parameter in a delcflink action.

    Source:GulfTech Security
    Published:15 Aug 2008
    4.3
    Medium

    CVE-2008-3700

    Last Modified: 5 Jan 2018

    Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the sessionid parameter in a livesupport startclientchat action to visitor/index.php; (2) the filter parameter in a news view action to index.php; or the Full Name field in a (3) account creation, (4) ticket opening, or (5) chat request operation.

    Source:GulfTech Security
    Published:15 Aug 2008
    6.8
    Medium

    CVE-2008-3682

    Last Modified: 14 Mar 2014

    SQL injection vulnerability in dpage.php in YPN PHP Realty allows remote attackers to execute arbitrary SQL commands via the docID parameter.

    Source:CraCkEr
    Published:14 Aug 2008
    7.5
    High

    CVE-2008-3681

    Last Modified: 1 Sept 2017

    components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the "first enabled user (lowest id)" password, typically for the administrator.

    Source:d3m0n
    Published:14 Aug 2008
    5
    Medium

    CVE-2008-3680

    Last Modified: 27 Apr 2011

    The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) by sending a type 0 packet with an invalid version followed by another packet to TCP port 3784.

    Source:Luigi Auriemma
    Published:14 Aug 2008
    4.3
    Medium

    CVE-2008-3679

    Last Modified: 13 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in IDevSpot PhpLinkExchange 1.01 allow remote attackers to inject arbitrary web script or HTML via the catid parameter in a (1) user_add, (2) recip, (3) tellafriend, or (4) contact action, or (5) in a request without an action; or (6) the id parameter in a tellafriend action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:sl4xUz
    Published:14 Aug 2008